Spec: a small full-stack app with real persistence and auth
The brief
Build a small app where a user creates an account, logs in, and manages a personal list of something — the specific domain matters far less than doing the mechanics for real. Recipes, workout logs, book notes, expense entries — pick something you'd actually plausibly use yourself, since that will keep you motivated past the boring middle part.
Requirements
- Real account creation and login (password hashing done properly, not stored in plain text) — this is the part of the spec that actually matters most; see the previous track's lessons on this if you haven't built auth before.
- Data persists in a real database, not in memory or local storage only.
- A user can only see and modify their own data — not because the UI happens to hide other people's, but because the backend actually enforces it.
- Deployed somewhere reachable by a URL, not just running on your own machine.
Why this is portfolio-worthy
This is the shape of an enormous fraction of real software jobs: accounts, ownership, a database, a deployed URL. Getting all four pieces working together — and being able to explain how ownership is enforced on the backend, specifically — demonstrates something a solo algorithm exercise can't.
What to avoid
Don't spend your limited time on visual polish before the four requirements above are solid — a plain-looking app where auth and ownership are done correctly beats a beautiful one where any logged-in user can edit anyone else's data. That specific bug is also a natural, honest thing to mention if an interviewer asks what you'd improve.
Resources
Curated resources for this node are on the way. Use what you already know how to search for, and check back soon.